Management System FAQs: Internal Audits

ISO Management System
ISO Management System

Qudos Management Pty Ltd.
April 2026

We often get asked questions about various aspects of management systems. So, we decided to put some of the more frequently-asked questions to one of our leading consultants.

Alan Jones - is Qudos CEO. he has decades of experience as a management system consultant, helping hundreds of businesses to implement management systems and achieve certification to various standards including ISO9001, ISO27001, ISO14001, and ISO45001. He has conducted certification audits against multiple standards, personally trained over 1,000 internal auditors, is a well-established public-speaker, author, and broadcaster, and has played a major role in the continuing development of Qudos3 IMS software. 

In this first post, the focus of FAQs is on Internal Audits - a mandatory requirement in all ISO certification standards.

FAQs:

We are developing a new management system and have had a Gap Analysis done. Do we also need to do internal audits?

Yes, they are two different activities. A Gap Analysis is typically performed when developing a new management system or making a significant change to an existing one. It considers if / how an organization meets a requirement of the standard. At that stage, the assessor is not really expecting to verify evidence of implementation.

An internal audit is seeking to verify that the organisation is actually implementing what it has planned and that is achieving requirements. In plain English, you are doing what you set out to do, and it is working. In this case, the auditor should definitely be seeking objective evidence.

Can internal audits only be carried out by employees?

Not at all. They may be carried out by anyone that can perform them competently and in an impartial and objective manner. That excludes those responsible for the work or subject being audited. It also excludes your certification auditor.

While it is commonplace for internal audits to be carried out by employees. There is nothing to stop some or all of them being done by a specialist contractor. In fact, that can be a very good option as it helps to ensure impartiality, frees up people to get on with what they do best, and can introduce external expertise to identify issues and opportunities for improvement. Of course, if you do plan to use a contractor, it would be great to know that they are ISO certified themselves!

Do internal auditors have to be qualified?

The ISO management system standards do not specify any qualification requirement for internal auditors. The are subject to the general requirement that people should be competent to perform the work assigned to them. So, what makes them competent? In general terms, they should have adequate technical knowledge to understand the subject of their audit, good communications / people skills are helpful, and they should have a clear understanding of their role as an auditor. So, some degree of training would be helpful and there are a number of internal auditor training options available. Taking it a step further, when we perform internal audits for clients, we ensure that the consultant is a fully trained and qualified certification auditor.

Does everything have to be audited every year?

No, it really doesn’t. I do sometimes see organisations attempt this, and it can lead to an unnecessary burden, or alternatively, a quick tick-and-flick exercise that offers little or no real value. The ISO standards clearly state that an internal audit programme should be established on the basis of risk. That means that that some things can be audited more frequently and more in-depth than others. The risk can be ascertained according to previous audit results, known issues, history of problems, and other factors.

An Internal audit programme should be looked at on a cost-benefit basis. While they are essential for ISO certification, we should concentrate our audits on what really matters -where problems can be eliminated and improvements made that will have a genuine effect.

It’s good to have back-stop so that everything does get audited say, every 3 years, but during that time, some things may be audited multiple times and perhaps at different locations or in different teams.

What is the biggest problem you see in organisation’s internal audit arrangements?

There is not really just one stand out issue but probably a combination of things – including those we have already discussed.

  • It may be a last-minute tick-and-flick exercise
  • It may be all left to one person
  • The same items being audited every time
  • The results not being communicated well or promptly to the responsible person
  • Data from the audits not being conveniently available to top management – they are not likely to trawl through a folder full of word-processed documents

I really do believe that a good internal audit programme can be a great driver to improvement for any business, and all of those problems mentioned can very easily be fixed with a simple yet effective system.

Contact us today to discuss how we can with your internal audit programme.

Internal Audit Service by one of our team of qualified ISO certification auditors

Click the LinkedIn Follow button below to follow Qudos and be the first to receive ISO management system news and further articles like this.